Notă
Accesul la această pagină necesită autorizare. Puteți încerca să vă conectați sau să modificați directoarele.
Accesul la această pagină necesită autorizare. Puteți încerca să modificați directoarele.
Important
This feature is in Beta. To use it, a workspace admin must turn on Governed agentic app-building from the Previews page. See Manage Azure Databricks previews.
An App Space is a governance boundary where admins define who can create and use apps, what permissions those apps have, and which spend policies apply to them.
Instead of having developers define resources and set permissions for each app, an App Space enables admins to configure permissions for groups of app developers.
App developers use Genie App Builder to build apps in an App Space.
Why use App Spaces
As coding agents make it easier to build apps, more people across an organization are creating them. App Spaces let business and other nontechnical users create apps that access data without breaking your organization's governance model. An admin defines the guardrails (identities, scopes, and resources) one time for a group of builders, and every app built in the space inherits them.
Create an App Space
You must be a workspace admin to create an App Space. You can create one in either of these ways:
- In the Databricks Apps UI, click App Spaces, then + New Space.
- Use the Azure Databricks REST API or the Terraform provider.
Note
You can't change an App Space's name after you create it.
Configure an App Space
As a workspace admin, you can configure:
- User authorization: what apps can do on behalf of users.
- Serverless usage policy: the serverless usage policy for apps in the space.
- Permissions: who can create apps in the space.
User authorization
User authorization, sometimes referred to as on-behalf-of-user (OBO) authorization, allows a Databricks app to act with the identity of the signed-in user. The app can only reach data and resources the user is already permitted to access, within the scopes you allow. See Configure authorization in a Databricks app.
An App Space lets admins restrict the roles and scopes that can be used with user authorization. Use user authorization when access should follow each user's existing Azure Databricks permissions, such as for Unity Catalog tables, Genie spaces and agents, or dashboards.
Role-based access control
Use role-based access control (RBAC) to limit app permissions and sharing. You can allow users to choose a role when signing in to an app, or require users to assume a specific role to use apps in the space.
In Azure Databricks, a role is implemented as a group. Group members can assume the role automatically. Other users need Assume permission. See Role-based access control (RBAC).
| Setting | Who can use apps | User authorization permissions |
|---|---|---|
| Any role | Anyone the developer shares their app with | The role chosen by the user when signing in to the app |
| Only the selected role | Users who can assume the selected role (if the app has been shared with them) | Only the selected role |
For example:
- An App Space uses Only the selected role with the group
emea-sales. - Jane Doe is a member of
emea-sales. - The app developer shares their app with Jane Doe.
- Jane must assume the
emea-salesrole to sign in to the app. - With user authorization, the app has access only to what
emea-salescan access (within allowed scopes), even if Jane Doe has additional grants and permissions.
Note
- To use Only the selected role, enable RBAC at the account and workspace levels.
- Only account groups can be used with role restrictions.
- Developers still have control over sharing their apps, even if a role is chosen.
- Assigning a role to an App Space does not grant users any new permissions. Users must simply have access to that role to use the app, even if a developer has shared their app with the user.
Scopes
Apps that use user authorization must declare specific authorization scopes to limit what the app can do on the user's behalf. See Configure authorization in a Databricks app.
In an App Space, you control the scopes that each app requests.
By default, a new App Space uses the Data + AI preset, which allows the following 11 scopes:
sql:restricted-querygeniecatalog.catalogs:readcatalog.schemas:readcatalog.tables:readfilesmodel-servingai-functionsai-gatewaymcp.externalmcp.functions
You can view or edit the selected scopes when you create or configure an App Space.
Serverless usage policy
Apps in a space run under a serverless usage policy. See Cost management tools on Azure Databricks.
Permissions
The following permissions control who can work in an App Space:
| Permission | Grants the ability to |
|---|---|
CAN CREATE APP |
Develop apps in the space |
CAN MANAGE |
Modify the space's settings |
CAN READ |
View the space, but not create apps in it (or necessarily use apps in it) |
Example use cases
You can shape an App Space around how a group works:
| Type | Description |
|---|---|
| Public apps | Apps shareable with anyone in the workspace. Can only access data and resources available to every workspace user. |
| Team apps | Apps built by a specific team, aligned with its existing role, infrastructure, data, and permissions. |
| Project apps | Apps associated with a defined project or engagement, sharing its provisioned tables, warehouses, pipelines, and access boundaries. |